AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0066 48.6 —
AFFECTED Product Versions Fixed Customer Support Ticket System & Helpdesk unspecified —
TIMELINE May 28 Reserved by CNA Jun 13 Published (CNA: Wordfence)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
22 CVEs published, led by Red Hat (4).
22 CVEs published June 13, 2026: 2 critical, 7 high, 9 medium, 4 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 3355 | 7816 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
348 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 95 | 1062 | 84 | 663 | 314 | 1 | 11 | 2 | 0.2 | 7.8 | .0013 | -118 ▼ |
| 591 | 766 | 67 | 406 | 272 | 21 | 77 | 6 | 0.8 | 8.1 | .0023 | +591 ▲ | |
| microsoft | 207 | 743 | 55 | 512 | 170 | 6 | 286 | 19 | 2.6 | 7.8 | .0044 | +70 ▲ |
| red hat | 44 | 138 | 8 | 57 | 62 | 11 | 2 | 0 | 0.0 | 6.7 | .0030 | +39 ▲ |
| apple | 14 | 66 | 1 | 21 | 42 | 2 | 88 | 7 | 10.6 | 5.7 | .0019 | -1 ▼ |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| debian | 2 | 2 | 0 | 0 | 2 | 0 | 1 | 0 | 0.0 | 6.5 | .0023 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | +17 ▲ |
| cisco | 3 | 15 | 5 | 4 | 6 | 0 | 56 | 9 | 60.0 | 7.5 | .0694 | +3 ▲ |
| palo alto networks | 9 | 11 | 1 | 2 | 7 | 1 | 13 | 2 | 18.2 | 5.9 | .0022 | +7 ▲ |
| ivanti | 4 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | +3 ▲ |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 ▲ |
| fortinet | 2 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | +1 ▲ |
| ubiquiti | 5 | 8 | 4 | 4 | 0 | 0 | 3 | 0 | 0.0 | 8.9 | .0052 | +5 ▲ |
| vmware | 3 | 4 | 0 | 2 | 2 | 0 | 7 | 1 | 25.0 | 6.7 | .0036 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 67 | 101 | 15 | 40 | 43 | 2 | 33 | 1 | 1.0 | 7.3 | .0052 | +63 ▲ |
| gitlab | 11 | 18 | 0 | 4 | 12 | 2 | 4 | 2 | 11.1 | 4.8 | .0024 | +11 ▲ |
| mozilla | 5 | 11 | 3 | 4 | 4 | 0 | 9 | 0 | 0.0 | 7.5 | .0032 | +1 ▲ |
| docker | 2 | 5 | 0 | 5 | 0 | 0 | 0 | 0 | 0.0 | 8.8 | .0021 | +2 ▲ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | 0 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| adobe | 124 | 126 | 4 | 48 | 72 | 2 | 19 | 2 | 1.6 | 5.5 | .0021 | +124 ▲ |
| ibm | 11 | 60 | 13 | 29 | 18 | 0 | 6 | 0 | 0.0 | 7.5 | .0028 | +11 ▲ |
| oracle | 2 | 30 | 10 | 16 | 4 | 0 | 27 | 2 | 6.7 | 8.1 | .0027 | +2 ▲ |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +5 ▲ |
| solarwinds | 3 | 6 | 2 | 3 | 1 | 0 | 10 | 4 | 66.7 | 7.8 | .6082 | +3 ▲ |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | +1 ▲ |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 ▲ |
| d-link | 9 | 11 | 0 | 4 | 2 | 5 | 3 | 0 | 0.0 | 5.5 | .0058 | +9 ▲ |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 0 | 0 | 0.0 | 7.5 | .0020 | +6 ▲ |
| abb | 5 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +5 ▲ |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | +3 ▲ |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| moxa | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.0 | .0007 | +1 ▲ |
| schneider electric | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0023 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 68 | 69 | 2 | 27 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0023 | +68 ▲ |
| sourcecodester | 36 | 58 | 0 | 0 | 24 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +36 ▲ |
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 2 | 46 | 1 | 11 | 13 | 21 | 0 | 0 | 0.0 | 6.2 | .0015 | +2 ▲ |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| helmholz | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| mb connect line | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| openclaw | 34 | 40 | 0 | 24 | 12 | 4 | 0 | 0 | 0.0 | 7.4 | .0022 | +34 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2026-50751 | .8377 | 99.7 | 9.3 |
| CVE-2026-42897 | .7120 | 99.4 | 8.1 |
| CVE-2026-45498 | .6308 | 99.1 | 7.5 |
| CVE-2026-49160 | .5383 | 98.9 | 7.5 |
| CVE-2026-10523 | .5187 | 98.9 | 9.8 |
| CVE-2026-28318 | .4001 | 98.5 | 7.5 |
| CVE-2026-53435 | .3766 | 98.4 | 8.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-45087 | 10.0 | .1296 | |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-47140 | 10.0 | .0082 | |
| CVE-2026-47208 | 10.0 | .0076 |
| Vendor | CVEs |
|---|---|
| 759 | |
| linux | 523 |
| microsoft | 235 |
| adobe | 124 |
| apache | 84 |
| red hat | 81 |
| spring | 69 |
| ibm | 60 |
| sourcecodester | 58 |
| edimax | 51 |
| Vendor | KEV |
|---|---|
| microsoft | 19 |
| cisco | 9 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| adobe | 2 |
| Ecosystem | Advisories |
|---|---|
| Maven | 35 |
| Packagist | 22 |
| PyPI | 11 |
| npm | 4 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-48595 | 0 | |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-28318 | SolarWinds | 0 |
| CVE-2026-34926 | Trend Micro, Inc. | 0 |
| CVE-2026-35273 | Oracle Corporation | 0 |
| CVE-2026-41091 | Microsoft | 0 |
| CVE-2026-42897 | Microsoft | 0 |
| CVE-2026-45247 | Mirasvit | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1669 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1669 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1669 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1669 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1669 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1669 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1669 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1669 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1669 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1669 |
EXPLOIT PUBLISHED — CVE-2026-12183 (Nefteprodukttekhnika LLC BUK TS-G Gas Station Automation System). Public exploit reference added.
How to read these box scores · glossary
22 CVEs published. 22 box scores, 0 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0066 48.6 —
AFFECTED Product Versions Fixed Customer Support Ticket System & Helpdesk unspecified —
TIMELINE May 28 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0058 45.2 —
AFFECTED Product Versions Fixed DCS-935L 1.10.01 – —
TIMELINE Jun 13 Reserved by CNA Jun 13 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0044 36.5 —
AFFECTED Product Versions Fixed BUK TS-G Gas Station Automation System 2.9.1 – —
TIMELINE Jun 13 Public exploit reference published Jun 13 Reserved by CNA Jun 13 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0044 36.2 —
AFFECTED Product Versions Fixed Online Scheduling and Appointment Booking System – Bookly unspecified —
TIMELINE Apr 3 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N N N 6.4 .0036 28.8 —
AFFECTED Product Versions Fixed Grafana Operator unspecified —
TIMELINE Jun 9 Reserved by CNA Jun 13 Published (CNA: GRAFANA)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0034 26.1 —
AFFECTED Product Versions Fixed LWS Optimize – All-in-One Speed Booster & Cache Tools unspecified —
TIMELINE Jun 12 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0032 23.7 —
AFFECTED Product Versions Fixed GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites unspecified —
TIMELINE May 20 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0030 22.1 —
AFFECTED Product Versions Fixed Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel unspecified —
TIMELINE May 20 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0029 21.2 —
AFFECTED Product Versions Fixed Page Builder: Pagelayer – Drag and Drop website builder unspecified —
TIMELINE Feb 13 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N L N 2.1 .0027 18.0 —
AFFECTED Product Versions Fixed CET Automated Grading System with AI Predictive Analytics 1.0 – —
TIMELINE Jun 13 Reserved by CNA Jun 13 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H R C L N N 3.4 .0025 15.9 —
AFFECTED Product Versions Fixed Store Locator WordPress unspecified —
TIMELINE May 20 Reserved by CNA Jun 13 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H L L 5.6 .0024 15.3 —
AFFECTED Product Versions Fixed Koha unspecified —
TIMELINE Apr 16 Reserved by CNA Jun 13 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0022 12.5 —
AFFECTED Product Versions Fixed Page Builder: Pagelayer – Drag and Drop website builder unspecified —
TIMELINE Feb 26 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H H H 9.4 .0022 12.2 —
AFFECTED Product Versions Fixed MCP Toolbox for Databases unspecified —
TIMELINE Jun 8 Reserved by CNA Jun 13 Published (CNA: Google)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0021 11.5 —
AFFECTED Product Versions Fixed Meow Gallery unspecified —
TIMELINE Jan 21 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0021 11.6 —
AFFECTED Product Versions Fixed Student Attendance Management System 1.0 – —
TIMELINE Jun 13 Reserved by CNA Jun 13 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0020 9.7 —
AFFECTED Product Versions Fixed Canvas unspecified —
TIMELINE May 26 Reserved by CNA Jun 13 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H H H 7.8 .0018 8.0 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 8 unspecified 0:2.10.9-26.el8_10 Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified —
TIMELINE Jun 12 Reserved by CNA Jun 13 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U N H N 5.5 .0018 7.2 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 8 unspecified 0:2.10.9-26.el8_10 Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified —
TIMELINE Jun 12 Reserved by CNA Jun 13 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H R U L L N 3.5 .0014 4.1 —
AFFECTED Product Versions Fixed Store Locator WordPress unspecified —
TIMELINE May 20 Reserved by CNA Jun 13 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H H H 7.8 .0013 3.1 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:2.1.11-61.el7_9 Red Hat Enterprise Linux 8 unspecified 0:2.10.9-26.el8_10 Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 0:2.10.9-25.el8_4.1 Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 0:2.10.9-25.el8_4.1 Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support unspecified 0:2.10.9-25.el8_6.1 Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On unspecified 0:2.10.9-25.el8_6.1 Red Hat Enterprise Linux 8.8 Telecommunications Update Service unspecified 0:2.10.9-25.el8_8.1 Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions unspecified 0:2.10.9-25.el8_8.1 Red Hat Enterprise Linux 6 unspecified —
TIMELINE Jun 12 Reserved by CNA Jun 13 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV L H L N U H H H 7.0 .0012 2.4 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:2.1.11-61.el7_9 Red Hat Enterprise Linux 8 unspecified 0:2.10.9-26.el8_10 Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 0:2.10.9-25.el8_4.1 Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 0:2.10.9-25.el8_4.1 Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support unspecified 0:2.10.9-25.el8_6.1 Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On unspecified 0:2.10.9-25.el8_6.1 Red Hat Enterprise Linux 8.8 Telecommunications Update Service unspecified 0:2.10.9-25.el8_8.1 Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions unspecified 0:2.10.9-25.el8_8.1 Red Hat Enterprise Linux 6 unspecified —
TIMELINE Jun 12 Reserved by CNA Jun 13 Published (CNA: redhat)
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-13 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.